CVE-2016-4568
- EPSS 0.13%
- Veröffentlicht 23.05.2016 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a crafted number of planes in a VIDIOC_DQBUF ioctl...
CVE-2016-4565
- EPSS 0.18%
- Veröffentlicht 23.05.2016 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI int...
- EPSS 0.27%
- Veröffentlicht 23.05.2016 10:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than ...
CVE-2016-4557
- EPSS 15.04%
- Veröffentlicht 23.05.2016 10:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted ...
CVE-2016-4486
- EPSS 0.52%
- Veröffentlicht 23.05.2016 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
CVE-2016-4485
- EPSS 0.51%
- Veröffentlicht 23.05.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
CVE-2016-4482
- EPSS 0.04%
- Veröffentlicht 23.05.2016 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTIN...
CVE-2015-0571
- EPSS 0.1%
- Veröffentlicht 09.05.2016 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify authorization for private SET IOCTL calls, which allows attackers to ...
CVE-2015-0570
- EPSS 0.06%
- Veröffentlicht 09.05.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other pro...
CVE-2015-0569
- EPSS 0.45%
- Veröffentlicht 09.05.2016 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices ...